[ubuntu/bionic-security] python-django 1:1.11.11-1ubuntu1.4 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Jul 1 13:59:20 UTC 2019


python-django (1:1.11.11-1ubuntu1.4) bionic-security; urgency=medium

  * SECURITY UPDATE: Incorrect HTTP detection with reverse-proxy
    connecting via HTTPS
    - debian/patches/CVE-2019-12781.patch: made HttpRequest always
      trusty SECURE_PROXY_SSL_HEADER if set in django/http/request.py,
      docs/ref/settings.txt and added tests to tests/settings_test/tests.py.
    - CVE-2019-12781
  * SECURITY UPDATE: XSS in Django admin via AdminURLFieldWidget
    - debian/patches/CVE-2019-12308.patch: made AdminURLFieldWidget
      validate URL before rendering clickable link in
      django/contrib/admin/templates/admin/widgets/url.html,
      django/contrib/admin/widgets.py add test test/admin_widgets/tests.py.
    - CVE-2019-12308

Date: 2019-06-24 16:25:58.452518+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list